{"id":"CVE-2026-107223","summary":"Excelize: Unbounded \u003ccol max\u003e attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process","details":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.","aliases":["GHSA-fq3v-74gv-27gm"],"modified":"2026-10-08T10:45:26.051723757Z","published":"2026-10-07T18:48:54.172Z","database_specific":{"cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107223.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107223.json"},{"type":"FIX","url":"https://github.com/qax-os/excelize/commit/a54c578af309fa81f448143ed2b7a91192cc58a7"},{"type":"FIX","url":"https://github.com/qax-os/excelize/pull/2370"},{"type":"ADVISORY","url":"https://github.com/qax-os/excelize/security/advisories/GHSA-fq3v-74gv-27gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107223"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qax-os/excelize","events":[{"introduced":"e51aff2d9562bbfb290ef76a948facb6d4660eff"},{"last_affected":"90ff348959dd842cbf3a4fbd93a78afbe18db476"}],"database_specific":{"extracted_events":[{"introduced":"2.1.0"},{"last_affected":"2.11.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.11.0","v2.10.1","v2.10.0","v2.9.1","v2.9.0","v2.8.1","v2.8.0","v2.7.1","v2.7.0","v2.6.1","v2.6.0","v2.5.0","v2.4.1","v2.4.0","v2.3.2","v2.3.1","v2.3.0","v2.2.0","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107223.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}